Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

1322 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat Updated

High [CVE-2026-71217] iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion

iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-20. Red Hat lists fixing advisory RHSA-2026:61680 with package iperf3-0:3.17.1-6.el10_2.1, iperf3-0:3.9-17.el9_8.1, iperf3-0:3.5-12.el8_10.1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-71217
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15567] Pre-auth denial of service on the IIOP listener

Pre-auth denial of service on the IIOP listener. Red Hat rates this important (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:53806. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15567
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15565] Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method

Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:53806. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15565
Unclassified
Aug 11, 2026
High7.4Red Hat

High [CVE-2026-15563] Missing authentication on EAP's IIOP NameService leads to MITM or DoS

Missing authentication on EAP's IIOP NameService leads to MITM or DoS. Red Hat rates this important (CVSS 7.4). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15563
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15562] integer overflow in MessageReader leads to pre-authentication denial of service

integer overflow in MessageReader leads to pre-authentication denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15562
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15561] OOM via missing limits in chunked trailer in EAP's Undertow

OOM via missing limits in chunked trailer in EAP's Undertow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15561
Unclassified
Aug 11, 2026
High8.1Red Hat

High [CVE-2026-15560] unauthed class loading via IIOP in EAP

unauthed class loading via IIOP in EAP. Red Hat rates this important (CVSS 8.1). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, openjdk-orb. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15560
Unclassified
Aug 11, 2026
High8.1Red Hat

High [CVE-2026-15556] picketlink SAML 2.0 auth bypass via missing assertions

picketlink SAML 2.0 auth bypass via missing assertions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7.

CVE-2026-15556
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-15555] wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller

wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-15555
Unclassified
Aug 11, 2026
High7.4Red Hat

High [CVE-2026-15554] Authentication Bypass via AJP ssl_cert/is_ssl Forgery

Authentication Bypass via AJP ssl_cert/is_ssl Forgery. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15554
Unclassified
Aug 11, 2026
High7.8Vendor: MediumRed Hat Updated

High [CVE-2026-72693] Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login

Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:41136 with package kbd-0:2.4.0-12.el9_8, kbd-0:2.6.4-8.el10_2, kbd-main-2.10.0-2.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.22.

CVE-2026-72693
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-72694] MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation

MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:57596 with package mrtg-0:2.17.10-12.el10_2.1, mrtg-0:2.17.7-12.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-72694
Unclassified
Aug 11, 2026
High7.9MS Server

High [CVE-2026-6726] MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse

MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-6726
Windows Server
Aug 11, 2026
High8.8MS Server

High [CVE-2026-62872] .NET Framework Elevation of Privilege Vulnerability

.NET Framework Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft.NET Framework 4.8 on Windows Server 2016; Microsoft.NET Framework 4.8 on Windows Server 2012 R2; Microsoft.NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016; Microsoft.NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012; and 4 more. Affected products named by the advisory: Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2; Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022; Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025; Microsoft .NET Framework 3.5 on Windows Server 2012 R2.

CVE-2026-62872
Windows Server
Aug 11, 2026
High7.8MS Server

High [CVE-2026-65810] .NET Framework Elevation of Privilege Vulnerability

.NET Framework Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft.NET Framework 4.8 on Windows Server 2016; Microsoft.NET Framework 4.8 on Windows Server 2012; Microsoft.NET Framework 4.8 on Windows Server 2012 R2; Microsoft.NET Framework 3.5 AND 4.8 on Windows Server 2019; and 4 more. Affected products named by the advisory: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022; Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019; Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016; Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012.

CVE-2026-65810
Windows Server
Aug 11, 2026
High7.8MS Server

High [CVE-2026-70354] .NET Core Remote Code Execution Vulnerability

.NET Core Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft.NET Framework 3.5 on Windows Server 2012; Microsoft.NET Framework 3.5 on Windows Server 2012 R2; Microsoft.NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016; Microsoft.NET Framework 3.5 AND 4.7.2 on Windows Server 2019; and 4 more. Affected products named by the advisory: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019; Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022; Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022; Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2.

CVE-2026-70354
Windows Server
Aug 11, 2026
High7.2Red Hat

High [CVE-2026-4757] Code execution and privilege escalation via VAPIX API improper input validation

Code execution and privilege escalation via VAPIX API improper input validation. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: axis.

CVE-2026-4757
Red Hat Enterprise Linux
Aug 11, 2026
High8.5Red Hat

High [CVE-2026-66797] Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin

Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin. Red Hat rates this important (CVSS 8.5). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66797
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-66798] Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods

Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66798
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-66799] Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement

Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:60390 with package rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787259060. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66799
Unclassified
Aug 11, 2026